The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Computer Games
Breach intelligence, attack campaigns, and threat reports targeting the Computer Games sector.
Explore Other Sectors
Computer Games Threat Reports
Gyazo Breach Exposes 23.6 Million Users: Server Vulnerability Leads to Massive Data Theft
On September 11, 2026, attackers exploited a server vulnerability in Gyazo's image-sharing platform to steal 23.6 million user records and 490 million image metadata entries. The breach exposed names, email addresses, password hashes, session IDs, and private image metadata including EXIF location data and OCR-extracted text. Gyazo detected the intrusion on September 12 and took the platform offline for maintenance, but the damage was already done with attackers potentially accessing private images and sensitive user information. This incident highlights the growing trend of attackers targeting cloud-based media platforms and the critical importance of server hardening as organizations increasingly rely on image-sharing services for business communications and collaboration.
6 days ago
Kill Chain
FBI Dismantles NightmareStresser: The Rise and Fall of a Major DDoS Empire
On September 17, 2026, the FBI seized the NightmareStresser DDoS-for-hire platform, one of the world's longest-running booter services that enabled cybercriminals to launch massive distributed denial-of-service attacks. The platform, operating through nightmare-stresser.com and nightmarestresser.org domains, boasted over 566,000 registered users and 52 dedicated servers capable of generating attacks up to 200 Gbps. Since 2022, NightmareStresser facilitated hundreds of thousands of DDoS attacks targeting victims worldwide, leveraging compromised IoT devices and routers as attack infrastructure. This seizure highlights the escalating threat of commoditized DDoS services that democratize cyberattacks, enabling even non-technical actors to launch sophisticated infrastructure attacks. The continued evolution of booter services represents a persistent challenge to organizations' availability and business continuity, particularly as these platforms increasingly target critical infrastructure and essential services.
1 week ago
Kill Chain
NightmareStresser Takedown: How US Authorities Disrupted a Massive DDoS Empire
In September 2026, the U.S. Department of Justice seized two domains associated with NightmareStresser, a distributed denial-of-service (DDoS)-for-hire service that facilitated hundreds of thousands of attacks since 2022. The platform operated with over 566,000 registered users across 52 servers, targeting educational institutions, government agencies, gaming platforms, and millions of individuals worldwide. The service offered advanced Layer 4 and Layer 7 attack capabilities, cryptocurrency payment options, and claimed 24/7 availability over eight years of operation. This seizure represents a critical escalation in the ongoing battle against cybercrime-as-a-service platforms, highlighting the urgent need for organizations to implement comprehensive DDoS protection and network security measures as these attacks continue to evolve in sophistication and scale.
1 week ago
Kill Chain
FBI Disrupts NightmareStresser: Major DDoS-for-Hire Takedown Exposes Cybercrime-as-a-Service Threats
In December 2024, the FBI and Royal Canadian Mounted Police seized the primary domain and associated websites of NightmareStresser, one of the longest-running and most popular DDoS-for-hire services used by cybercriminals globally. Operating since at least 2022, the service facilitated hundreds of thousands of DDoS attacks against educational institutions, government agencies, gaming platforms, and millions of individuals worldwide. The takedown was part of Operation PowerOFF, an ongoing international effort targeting IP stressers and booter services that make DDoS attacks accessible to non-technical users through user-friendly interfaces and tutorials. This incident highlights the persistent threat of commoditized cyber attack services that democratize sophisticated attack capabilities, enabling script kiddies and low-skilled threat actors to launch disruptive campaigns against critical infrastructure and services with minimal technical expertise required.
1 week ago
Kill Chain
Google Play Early Access Exploited: How Thousands of Deceptive Apps Bypassed Security
In September 2026, cybersecurity researchers discovered threat actors systematically abusing Google Play's Early Access program to distribute thousands of deceptive Android applications. These malicious apps promised financial rewards, casino winnings, and premium content while exploiting the program's feature that prevents user reviews and ratings. Notable examples included fake casino games and a Grand Theft Auto imitator called "Vice Streets: Open World" with over 1 million downloads. The attackers promoted these apps through social media platforms using AI-generated celebrity deepfakes, ultimately generating revenue through excessive advertising while never delivering promised payouts to users. This incident highlights the growing sophistication of mobile malware campaigns that exploit legitimate platform features to bypass traditional security mechanisms. The abuse of Early Access programs represents an emerging trend where attackers leverage regulatory gaps and user trust mechanisms to distribute deceptive applications at scale.
2 weeks ago
Kill Chain
Inside CL-CRI-1171: The Massive Pay-Per-Install Network That Hid in Plain Sight
In September 2026, Unit 42 researchers uncovered CL-CRI-1171, a sophisticated pay-per-install (PPI) malware distribution network that operated undetected for over two years. The cybercrime group leveraged YouTube gaming channels with hundreds of thousands of followers and SEO poisoning techniques to distribute multiple malware families including Insomnia RAT, ARKTunnel, and Docro Hijacker. The operation used OfferLoader, a custom Inno Setup-based loader, to deploy over 10,000 distinct payload combinations across corporate networks, critical infrastructure, and government entities while evading detection through clever gating mechanisms and unremarkable appearance. This campaign highlights the growing threat of commodity infrastructure being weaponized for large-scale malware distribution, particularly as threat actors increasingly target younger demographics through gaming platforms and use legitimate-seeming tools to bypass security scrutiny.
2 weeks ago
Kill Chain
REVSTEALER's Four-Module Attack: How Infostealers Are Evolving Beyond Credential Theft
In September 2026, Elastic Security Labs documented four previously unreported modules associated with REVSTEALER, a commercial Windows information stealer active since February 2026. The malware initially operates as a traditional infostealer, harvesting browser credentials, cryptocurrency wallets, gaming accounts, and messaging data before deleting itself. However, four persistent modules remain on infected systems: ProManager (wallet overlay attacks), WinUpdate (clipboard cryptocurrency address replacement), SoftManager (reverse proxy), and LockAppHost (disables Windows Update and Defender to run cryptocurrency miners). The malware spreads primarily through game cheat lures on compromised YouTube channels and fake AI applications. This incident highlights the evolution of infostealers beyond simple credential theft toward persistent system compromise and resource abuse. As threat actors increasingly combine multiple attack vectors in single campaigns, organizations face compound risks from credential harvesting, system weakening, and unauthorized resource consumption that can persist long after the initial infection appears resolved.
2 weeks ago
Kill Chain
CyberLeek's GTA VI Data Theft: How Gaming's Biggest Leak Redefined Cyber Extortion
In late 2024, threat actor 'CyberLeek' launched a sophisticated data theft and extortion campaign against Rockstar Games, leaking pre-release gameplay footage from the highly anticipated Grand Theft Auto VI game. The attacker published proprietary content across multiple platforms including Discord, demonstrating either insider access or a significant breach of Rockstar's development systems. The incident caused substantial reputational damage and prompted aggressive legal action from Take-Two Interactive, including federal subpoenas against Discord, Google, Microsoft, and X to identify the perpetrators. The attack employed a novel monetization strategy, combining cryptocurrency schemes with watermarked stolen content and crowdsourced pressure tactics to maximize financial gain from the leaked intellectual property. This incident represents an evolution in data extortion tactics, where threat actors leverage public anticipation and social media amplification to maximize pressure on victims. The attack demonstrates how modern cybercriminals are adapting traditional ransomware playbooks to target high-value intellectual property in the entertainment industry, creating new challenges for incident response and legal remediation.
4 weeks ago
Kill Chain
Weedhack Malware Campaign Exploits Minecraft Community Through Advanced SEO Manipulation
In August 2026, cybersecurity researchers discovered that the Weedhack malware family continues to actively target Minecraft gamers through sophisticated SEO poisoning campaigns and fake gaming websites. The attackers created convincing replicas of legitimate Minecraft clients and tools, using platforms like Discord, MediaFire, and GitHub to distribute malicious JAR files. McAfee Labs detected over 6,300 attempts to access these malicious sites, which successfully outranked legitimate sources in search engine results. The malware establishes persistence by disabling Microsoft Defender, stealing sensitive data, and maintaining command and control communications. This incident highlights the growing sophistication of gaming-focused malware campaigns and the increasing use of AI-powered tools to create convincing fake websites. The success of these SEO poisoning techniques demonstrates how threat actors are adapting their distribution methods to exploit trusted platforms and search engine algorithms.
1 month ago
Kill Chain
UAT-10147 Cybercrime Group Weaponizes AI for Massive Server Attack Campaign
In August 2026, cybersecurity researchers disclosed details of UAT-10147, a Chinese-speaking cybercrime group leveraging AI-powered tools to conduct large-scale attacks against Windows and Linux web servers globally. The threat actor deployed artificial intelligence frameworks including PentestGPT, DeepAudit, and custom AI-generated Python scripts to automate vulnerability exploitation, reconnaissance, and payload generation across approximately 170,000 target URLs. UAT-10147 exploited known vulnerabilities to establish initial access, then deployed the cross-platform SPECTRE implant featuring advanced EDR bypass capabilities and Linux rootkit functionality, primarily targeting education, media, technology, and gaming sectors in Brazil, Bolivia, China, Canada, and Vietnam for SEO fraud and data theft operations. This incident represents a significant evolution in cybercrime operations, demonstrating how threat actors are integrating AI capabilities to scale attacks and enhance operational efficiency. The emergence of AI-driven offensive frameworks marks a critical shift in the threat landscape, enabling lower-skilled actors to conduct sophisticated attacks while highlighting the urgent need for organizations to strengthen their security postures against automated exploitation campaigns.
1 month ago
Kill Chain
Valve Alerts Steam Hardware Customers to Data Breach via CEVA Logistics
Between July 29 and August 1, 2026, CEVA Logistics, the shipping partner for Valve's Steam hardware in Europe, experienced a cyberattack that compromised customer data. The attackers accessed names, addresses, phone numbers, email addresses, and details of purchased products. Valve confirmed that sensitive information such as payment details and Steam account credentials remained secure, as CEVA does not have access to this data. Affected customers have been notified and advised to be vigilant against potential phishing attempts. This incident underscores the vulnerabilities in supply chain partnerships and the importance of robust security measures across all entities handling customer data. As cyberattacks targeting third-party service providers become more prevalent, organizations must ensure comprehensive security protocols are in place to protect end-user information.
1 month ago
Kill Chain
Massive npm Supply Chain Attack Delivers Cross-Platform Malware
In August 2026, a significant supply chain attack was identified involving nearly 800 malicious packages published to the npm registry. These packages, designed to deliver cross-platform malware, targeted Windows, macOS, and Linux systems. Unlike typical npm attacks that exploit lifecycle hooks, these packages instructed developers to load them using the require() function, leading to the execution of a downloader named WEL1DROPPER. This downloader determined the host's operating system and processor architecture, subsequently fetching a compatible payload from specified Cloudflare Workers hosts. If HTTPS-based downloads failed, the malware utilized DNS TXT records to obtain the next-stage payload from the domain 'wel1[.]ru'. The final payloads established persistence, interfered with monitoring tools, and executed various malicious activities, including deploying the Sliver command-and-control framework on Linux systems. This incident underscores the evolving sophistication of supply chain attacks within the open-source ecosystem. The attackers' use of AI-generated typo-squatting package names and unconventional execution methods highlights the need for enhanced vigilance among developers and organizations. As software supply chains become increasingly complex, the potential for widespread compromise grows, emphasizing the importance of robust security practices and continuous monitoring to detect and mitigate such threats.
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports